Threat Overview
UAC-0050, publicly tracked by several threat intelligence organizations and also known as Mercenary Akula, has been active since at least 2020. The group is widely assessed to be a Russia-aligned mercenary threat actor with operations focused on cyber espionage, financial theft, and intelligence collection
Unlike many advanced threat groups that rely heavily on custom malware families, UAC-0050 consistently leverages legitimate software and publicly available infrastructure to achieve its objectives. This operational model allows the actor to minimize infrastructure development while blending malicious activity into normal enterprise traffic
Public reporting has linked the group to multiple aliases, including:
- UAC-0050
- Mercenary Akula
- DaVinci Group
- Agency DaVinci
Threat intelligence reporting, including assessments from CERT-UA, associates the group with Russian law enforcement interests and documents its continued targeting of Ukrainian government entities, administrative organizations, and financially relevant institutions
Historically, UAC-0050 has demonstrated expertise in:
- Targeted spear-phishing campaigns
- Trusted-brand impersonation
- Intelligence collection
- Financial fraud enablement
- Commercial remote access software abuse
- Information-psychological operations
Rather than relying solely on advanced malware development, the actor frequently combines legitimate cloud platforms, commercially available administration tools, and convincing social engineering to establish access while reducing opportunities for detection
Threat Actor Evolution
Over the past several years, UAC-0050 has gradually expanded both its operational capabilities and targeting priorities
Earlier campaigns primarily focused on Ukrainian governmental organizations and public-sector entities through phishing emails impersonating trusted institutions. Subsequent reporting throughout 2024 showed the actor broadening its objectives to include financially motivated operations while maintaining its espionage capabilities
Rather than changing its technical methodology, the actor refined existing techniques by abusing trusted cloud services and commercial software instead of deploying increasingly sophisticated malware
Public reporting has documented repeated abuse of services including:
- Dropbox
- Google Drive
- Bitbucket
- GitHub
- 4Sync
- Public file-sharing platforms
Likewise, commercial remote administration software has become a defining characteristic of the group’s operations. Previous campaigns have leveraged:
- Remote Manipulator System (RMS)
- LiteManager
- Remote Utilities
- Remcos RAT
- QuasarRAT
- NetSupport RAT
This consistent reliance on legitimate administration software significantly complicates defensive operations because network traffic generated by these applications often resembles authorized remote management activity
The February 2026 campaign continues this established pattern while introducing a strategically significant victim profile